CVE-2023-42436

Source
https://cve.org/CVERecord?id=CVE-2023-42436
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-42436.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-42436
Published
2023-12-26T07:22:50.373Z
Modified
2026-08-27T03:57:00.908463104Z
Summary
[none]
Details

Stored cross-site scripting vulnerability exists in the presentation feature of GROWI versions prior to v3.4.0. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the site using the product.

Database specific
{
    "cna_assigner": "jpcert",
    "unresolved_ranges": [
        {
            "source": "AFFECTED_FIELD",
            "extracted_events": [
                {
                    "introduced": "prior to v3.4.0"
                },
                {
                    "last_affected": "prior to v3.4.0"
                }
            ]
        }
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/42xxx/CVE-2023-42436.json"
}
References

Affected packages

Git / github.com/growilabs/growi

Affected ranges

Type
GIT
Repo
https://github.com/growilabs/growi
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "cpe": "cpe:2.3:a:weseek:growi:*:*:*:*:*:*:*:*",
    "source": "CPE_RANGE",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "3.4.0"
        }
    ]
}

Affected versions

1.*
1.0.0-RC3
v1.*
v1.0.0-RC
v1.0.0-RC2
v1.0.0-RC4
v1.3.0
v1.3.1
v1.4.0
v1.5.0
v1.5.1
v1.5.2
v1.5.3
v1.6.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-42436.json"